What is used
| Technology / processing | Purpose | Status | Typical duration |
|---|---|---|---|
| PHP session cookie | Security, CSRF protection, private reservation access and authenticated administration. | Essential | Session / server session lifetime. |
talkymind_privacy_v4 local storage | Remembers your optional-analytics choice and the interface state of your privacy preferences. | Privacy preference | Until cleared, replaced or the notice version changes. |
tm_aggregate_optout cookie | Used only when you object to cookie-free aggregate traffic measurement so the server can honour that choice on future requests. | Privacy preference requested by you | Up to 180 days, then renewed only if you choose the preference again. |
| Cookie-free server-side aggregate request counters | Counts public page requests by coarse categories such as page, day/hour, country code supplied by Cloudflare, traffic-source category, known search/social referrer class, primary language, coarse device/browser/OS family and HTTP status. | No analytics cookie, localStorage identifier, fingerprint or visitor/session ID is created for this layer. You can object in Privacy choices; DNT and Global Privacy Control are also respected. | Aggregate counters: 395 days by default. Raw IP addresses, raw user-agent strings, query strings and full referrer URLs are not stored by this layer. |
| First-party interaction analytics | Page/event statistics such as CTA clicks, form starts, scroll-depth milestones and engagement events. | Optional; off until accepted | 90 days by default. |
| Google Analytics 4 | Third-party measurement only if the operator has configured a GA4 ID. | Optional; not loaded until accepted | Controlled by the configured Google Analytics property and applicable consent settings. |
How cookie-free aggregate measurement works
When a public page is requested, the web server necessarily receives ordinary connection/request information. For TalkyMind's aggregate layer, that information is reduced immediately to coarse counters. The application does not write the raw IP address, raw user-agent string, URL query string, full referrer URL, advertising identifier, fingerprint, booking identity, contact identity or an analytics visitor/session identifier into the aggregate analytics table.
Country is taken only from Cloudflare's coarse country header when available; the application does not perform its own IP geolocation for this purpose. A referrer is reduced to a traffic-source class; only recognised major search/social platform hostnames are retained as aggregate labels, while other external referrers are grouped as “Other external”. User-agent and language headers are reduced to coarse categories before counting. The resulting counters cannot be used by this application to reconstruct a person's clickstream across pages.
This processing is designed to rely on a minimal legitimate-interest/service-measurement basis where that basis is available and the required balancing test supports it. It does not attempt to use legitimate interests to bypass consent rules that apply to storage or access on a user's device. Optional interaction analytics and GA4 remain consent-gated.
Your choices
Accepting optional analytics is not required to contact or book. Rejecting optional analytics does not reduce the core service. You can also object to future inclusion in the cookie-free aggregate request counters. To manage either choice:
If your browser sends Do Not Track: 1 or Global Privacy Control, TalkyMind's application-level aggregate counter is skipped for that request. Security and abuse-prevention processing that is necessary to protect the service is separate from analytics and may still occur.
Consent withdrawal
Changing optional analytics to reject stops new consent-based first-party analytics and prevents GA4 from being initiated by this website. It does not retroactively erase statistics already lawfully recorded; those records follow the retention schedule in the Privacy Notice.
Enabling the aggregate-measurement objection applies to future requests after the preference reaches the server. Because the aggregate table contains counters rather than an analytics visitor identifier, previously aggregated counts cannot be isolated back to a particular person.